xref: /openbsd/regress/sbin/ipsecctl/ike65.ok (revision 8529ddd3)
1C set [Phase 1]:1.1.1.1=peer-1.1.1.1 force
2C set [peer-1.1.1.1]:Phase=1 force
3C set [peer-1.1.1.1]:Address=1.1.1.1 force
4C set [peer-1.1.1.1]:Configuration=phase1-peer-1.1.1.1 force
5C set [phase1-peer-1.1.1.1]:EXCHANGE_TYPE=ID_PROT force
6C add [phase1-peer-1.1.1.1]:Transforms=phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128-MODP_1024 force
7C set [phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128-MODP_1024]:AUTHENTICATION_METHOD=RSA_SIG force
8C set [phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128-MODP_1024]:HASH_ALGORITHM=SHA force
9C set [phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128-MODP_1024]:ENCRYPTION_ALGORITHM=AES_CBC force
10C set [phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128-MODP_1024]:KEY_LENGTH=128,128:256 force
11C set [phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128-MODP_1024]:GROUP_DESCRIPTION=MODP_1024 force
12C set [phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128-MODP_1024]:Life=LIFE_MAIN_MODE force
13C set [peer-1.1.1.1]:ID=id-2.2.2.2 force
14C set [id-2.2.2.2]:ID-type=IPV4_ADDR force
15C set [id-2.2.2.2]:Address=2.2.2.2 force
16C set [peer-1.1.1.1]:Remote-ID=id-1.1.1.1 force
17C set [id-1.1.1.1]:ID-type=IPV4_ADDR force
18C set [id-1.1.1.1]:Address=1.1.1.1 force
19C set [from-10.1.1.0/24-to-10.1.2.0/24]:Phase=2 force
20C set [from-10.1.1.0/24-to-10.1.2.0/24]:ISAKMP-peer=peer-1.1.1.1 force
21C set [from-10.1.1.0/24-to-10.1.2.0/24]:Configuration=phase2-from-10.1.1.0/24-to-10.1.2.0/24 force
22C set [from-10.1.1.0/24-to-10.1.2.0/24]:Local-ID=from-10.1.1.0/24 force
23C set [from-10.1.1.0/24-to-10.1.2.0/24]:Remote-ID=to-10.1.2.0/24 force
24C set [phase2-from-10.1.1.0/24-to-10.1.2.0/24]:EXCHANGE_TYPE=QUICK_MODE force
25C set [phase2-from-10.1.1.0/24-to-10.1.2.0/24]:Suites=phase2-suite-from-10.1.1.0/24-to-10.1.2.0/24 force
26C set [phase2-suite-from-10.1.1.0/24-to-10.1.2.0/24]:Protocols=phase2-protocol-from-10.1.1.0/24-to-10.1.2.0/24 force
27C set [phase2-protocol-from-10.1.1.0/24-to-10.1.2.0/24]:PROTOCOL_ID=IPSEC_ESP force
28C set [phase2-protocol-from-10.1.1.0/24-to-10.1.2.0/24]:Transforms=phase2-transform-from-10.1.1.0/24-to-10.1.2.0/24-AES128-SHA2_256-MODP_1024-TUNNEL force
29C set [phase2-transform-from-10.1.1.0/24-to-10.1.2.0/24-AES128-SHA2_256-MODP_1024-TUNNEL]:TRANSFORM_ID=AES force
30C set [phase2-transform-from-10.1.1.0/24-to-10.1.2.0/24-AES128-SHA2_256-MODP_1024-TUNNEL]:KEY_LENGTH=128,128:256 force
31C set [phase2-transform-from-10.1.1.0/24-to-10.1.2.0/24-AES128-SHA2_256-MODP_1024-TUNNEL]:ENCAPSULATION_MODE=TUNNEL force
32C set [phase2-transform-from-10.1.1.0/24-to-10.1.2.0/24-AES128-SHA2_256-MODP_1024-TUNNEL]:AUTHENTICATION_ALGORITHM=HMAC_SHA2_256 force
33C set [phase2-transform-from-10.1.1.0/24-to-10.1.2.0/24-AES128-SHA2_256-MODP_1024-TUNNEL]:GROUP_DESCRIPTION=MODP_1024 force
34C set [phase2-transform-from-10.1.1.0/24-to-10.1.2.0/24-AES128-SHA2_256-MODP_1024-TUNNEL]:Life=LIFE_QUICK_MODE force
35C set [from-10.1.1.0/24]:ID-type=IPV4_ADDR_SUBNET force
36C set [from-10.1.1.0/24]:Network=10.1.1.0 force
37C set [from-10.1.1.0/24]:Netmask=255.255.255.0 force
38C set [to-10.1.2.0/24]:ID-type=IPV4_ADDR_SUBNET force
39C set [to-10.1.2.0/24]:Network=10.1.2.0 force
40C set [to-10.1.2.0/24]:Netmask=255.255.255.0 force
41C add [Phase 2]:Connections=from-10.1.1.0/24-to-10.1.2.0/24
42